Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A government agency is modernizing its applications and moving them to Azure Kubernetes Service (AKS). Due to strict compliance regulations, all inbound traffic to the AKS cluster must be subject to advanced threat protection, including Layer 7 inspection, SQL injection protection, and bot mitigation. Additionally, the agency requires a centralized point of entry for all applications hosted within AKS. Which Azure service should be deployed in front of the AKS cluster to meet these requirements?

  1. AAzure Firewall
  2. BAzure Application Gateway with WAF
  3. CAzure Traffic Manager
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: B. Azure Application Gateway with WAF

Azure Application Gateway with Web Application Firewall (WAF) provides Layer 7 inspection, SQL injection protection, and bot mitigation, which are crucial for protecting web applications exposed via AKS. It also acts as a centralized entry point and load balancer for HTTP/S traffic.

Why the other options are wrong

  • A. Azure Firewall provides network-level (Layer 3/4) protection and advanced features but is not a Web Application Firewall.
  • C. Azure Traffic Manager is a DNS-based traffic routing service and does not provide any security features like WAF.
  • D. Azure Load Balancer operates at Layer 4 and does not provide Layer 7 inspection or WAF capabilities.

Azure Application Gateway WAF

Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. Its Web Application Firewall (WAF) capability provides centralized protection of your web applications from common exploits and vulnerabilities.

  • Layer 7 load balancing for HTTP/S traffic.
  • Integrated Web Application Firewall (WAF).
  • Protects against SQL injection, XSS, bot attacks.
  • Supports URL-based routing and SSL/TLS termination.

Memory trick: App Gateway Protects Web, Firewall Protects Network, Load Balancer Distributes.

More Design security for infrastructure questions